signals-scout-general

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted event data from the PostHog project, creating a surface for indirect prompt injection.
  • Ingestion points: Data is ingested via tools such as read-data-schema, execute-sql, query-logs, and inbox-reports-retrieve in SKILL.md.
  • Boundary markers: The instructions do not specify explicit delimiters or boundary markers when interpolating retrieved data into prompts for analysis.
  • Capability inventory: The skill can perform write actions via emit_report, edit_report, and scout-scratchpad-remember.
  • Sanitization: There are no documented sanitization or filtering steps for the ingested data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 04:00 PM
Security Audit — agent-trust-hub — signals-scout-general